You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Using 36 (26+10) symbols and 11 digit for the token length, we have 36^11 (1.316217e+17) possible tokens. We suppose that randomization really works randomly.
Is a brute-force research undoubtedly unfeasible? It depends.
I say "it depends" because, the difficulty decreases as the number of tokens stored increase.
Probably none of the applications that use this library will ever get enough tokens stored to be a plausible security threat. But add the 'email' field in the 'password_reset/confirm/' view can solve the problem.
The text was updated successfully, but these errors were encountered:
marinimau
changed the title
Token key space
Please add email field to perform confirm request
Mar 16, 2020
Using 36 (26+10) symbols and 11 digit for the token length, we have 36^11 (1.316217e+17) possible tokens. We suppose that randomization really works randomly.
Is a brute-force research undoubtedly unfeasible? It depends.
I say "it depends" because, the difficulty decreases as the number of tokens stored increase.
Probably none of the applications that use this library will ever get enough tokens stored to be a plausible security threat. But add the 'email' field in the 'password_reset/confirm/' view can solve the problem.
The text was updated successfully, but these errors were encountered: